Vulnerabilities (CVE)

Filtered by CWE-89
Total 20788 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-41702 1 Siberiancms 1 Siberiancms 2026-06-17 N/A 9.8 CRITICAL
SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-41679 1 Glpi-project 1 Glpi 2026-06-17 N/A 6.5 MEDIUM
GLPI is a free asset and IT management software package. An authenticated user can exploit a SQL injection vulnerability from the ticket form. Upgrade to 10.0.17.
CVE-2024-41618 2026-06-17 N/A 9.8 CRITICAL
Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to SQL Injection in the `transaction_delete_group` function. The vulnerability is due to improper sanitization of user input in the `TrDeleteArr` parameter, which is directly incorporated into an SQL query.
CVE-2024-41579 2026-06-17 N/A 9.8 CRITICAL
DTStack Taier 1.4.0 allows remote attackers to specify the jobName parameter in the console listNames function to cause a SQL injection vulnerability
CVE-2024-41551 1 Campcodes 1 Supplier Management System 2026-06-17 N/A 9.8 CRITICAL
CampCodes Supplier Management System v1.0 is vulnerable to SQL injection via Supply_Management_System/admin/view_order_items.php?id= .
CVE-2024-41550 1 Campcodes 1 Supplier Management System 2026-06-17 N/A 7.2 HIGH
CampCodes Supplier Management System v1.0 is vulnerable to SQL injection via Supply_Management_System/admin/view_invoice_items.php?id= .
CVE-2024-41512 1 4pace 1 Cadclick 2026-06-17 N/A 8.8 HIGH
A SQL Injection vulnerability in "ccHandler.aspx" in all versions of CADClick v.1.11.0 and before allows remote attackers to execute arbitrary SQL commands via the "bomid" parameter.
CVE-2024-41444 1 Seacms 1 Seacms 2026-06-17 N/A 9.8 CRITICAL
SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so.
CVE-2024-41372 1 Organizr 1 Organizr 2026-06-17 N/A 9.8 CRITICAL
Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/settyping.php.
CVE-2024-41370 1 Organizr 1 Organizr 2026-06-17 N/A 9.8 CRITICAL
Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/setlike.php.
CVE-2024-41238 1 Lopalopa 1 Responsive School Management System 2026-06-17 N/A 5.3 MEDIUM
A SQL injection vulnerability in /smsa/student_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter.
CVE-2024-41237 1 Lopalopa 1 Responsive School Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in /smsa/teacher_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter.
CVE-2024-41236 1 Lopalopa 1 Responsive School Management System 2026-06-17 N/A 7.2 HIGH
A SQL injection vulnerability in /smsa/admin_login.php in Kashipara Responsive School Management System v3.2.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter of the Admin Login Page
CVE-2024-40689 1 Ibm 2 Infosphere Information Server, Infosphere Information Server On Cloud 2026-06-17 N/A 6.0 MEDIUM
IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. IBM X-Force ID: 297719.
CVE-2024-40638 1 Glpi-project 1 Glpi 2026-06-17 N/A 8.1 HIGH
GLPI is a free asset and IT management software package. An authenticated user can exploit multiple SQL injection vulnerabilities. One of them can be used to alter another user account data and take control of it. Upgrade to 10.0.17.
CVE-2024-40637 1 Getdbt 1 Dbt Core 2026-06-17 N/A 4.2 MEDIUM
dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to build applications. When a user installs a package in dbt, it has the ability to override macros, materializations, and other core components of dbt. This is by design, as it allows packages to extend and customize dbt's functionality. However, this also means that a malicious package could potentially override these components with harmful code. This issue has been fixed in versions 1.8.0, 1.6.14 and 1.7.14. Users are advised to upgrade. There are no kn own workarounds for this vulnerability. Users updating to either 1.6.14 or 1.7.14 will need to set `flags.require_explicit_package_overrides_for_builtin_materializations: False` in their configuration in `dbt_project.yml`.
CVE-2024-40614 1 Egroupware 1 Egroupware 2026-06-17 N/A 9.8 CRITICAL
EGroupware before 23.1.20240624 mishandles an ORDER BY clause. This leads to json.php?menuaction=EGroupware\Api\Etemplate\Widget\Nextmatch::ajax_get_rows sort.id SQL injection by authenticated users for Address Book or InfoLog sorting.
CVE-2024-40570 1 Seacms 1 Seacms 2026-06-17 N/A 6.5 MEDIUM
SQL Injection vulnerability in SeaCMS v.12.9 allows a remote attacker to obtain sensitive information via the admin_datarelate.php component.
CVE-2024-40560 1 Project Team 1 Tmall Demo 2026-06-17 N/A 7.3 HIGH
Tmall_demo before v2024.07.03 was discovered to contain a SQL injection vulnerability.
CVE-2024-40542 1 Codermy 1 My-springsecurity-plus 2026-06-17 N/A 9.8 CRITICAL
my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /api/role?offset.